An
Email with the Subject "Re: [ibps] TR: Phishing" was
received in one of Scamdex's honeypot email accounts on Tue, 13 Oct 2020 17:57:02 -0700 (PDT)
and has been classified as a Generic Scam Email.
The sender shows as Emilie DAVEAU <emilie.daveau@upmc.fr>.
The email address was probably spoofed. Do not reply to or contact any persons or organizations referenced in
this email, or follow any URLs as you may expose yourself to scammers and, at the very least, you will be
added to their email address lists for spam purposes.
This a (redacted) view of the raw email headers of this scam email.
Personally Identifiable Information (PII) has been suppressed, but can be
supplied as received to appropriate investigating or law enforcement agencies on request.
EEEEEstdClass Object
(
[delivered-to:] => scamdex@gmail.com
[received:] => Array
(
[0] => by 2002:a02:cb08:0:0:0:0:0 with SMTP id j8csp168029jap; Tue, 13 Oct 2020 17:57:02 -0700 (PDT)
[1] => from mail-sor-f41.google.com (mail-sor-f41.google.com. [209.85.220.41]) by mx.google.com with SMTPS id d15sor464228oig.64.2020.10.13.17.57.02 for (Google Transport Security); Tue, 13 Oct 2020 17:57:02 -0700 (PDT)
[2] => from imta-38.everyone.net (imta-36.everyone.net. [216.200.145.36]) by gmr-mx.google.com with ESMTPS id r6si288144oth.4.2020.10.13.17.57.01 for (version=TLS1_2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128/128); Tue, 13 Oct 2020 17:57:01 -0700 (PDT)
[3] => from pps.filterd (omta002.sj2.proofpoint.com [127.0.0.1]) by imta-38.everyone.net (8.16.0.43/8.16.0.43) with SMTP id 09E0sPra010701; Tue, 13 Oct 2020 17:55:54 -0700
[4] => from shiva144.upmc.fr (shiva144.upmc.fr [134.157.0.144]) by m0117123.mta.everyone.net (EON-INBOUND) with ESMTP id m0117123.5f62b24b.11132b4 for ; Tue, 13 Oct 2020 17:55:51 -0700
[5] => from shiva144.upmc.fr (localhost [127.0.0.1]) by shiva144.upmc.fr (Postfix) with ESMTP id 3DCC82D167; Wed, 14 Oct 2020 02:55:50 +0200 (CEST)
[6] => from courriel.upmc.fr (courriel4.reseau.jussieu.fr [134.157.0.195]) by shiva144.upmc.fr (Postfix) with ESMTP id 162752D17C; Wed, 14 Oct 2020 02:55:50 +0200 (CEST)
[7] => from localhost (localhost [127.0.0.1]) by courriel.upmc.fr (8.14.5/jtpda-5.5pre1) with ESMTP id 09E0tk0s066315 ; Wed, 14 Oct 2020 02:55:47 +0200 (CEST) (envelope-from emilie.daveau@upmc.fr)
[8] => from 102.141.212.14 (102.141.212.14 [102.141.212.14]) by courriel.upmc.fr (Horde Framework) with HTTP; Wed, 14 Oct 2020 02:55:45 +0200
)
[x-received:] => Array
(
[0] => by 2002:a4a:5385:: with SMTP id n127mr1512593oob.63.1602637022284; Tue, 13 Oct 2020 17:57:02 -0700 (PDT)
[1] => by 2002:aca:aa91:: with SMTP id t139mr651321oie.45.1602637021991; Tue, 13 Oct 2020 17:57:01 -0700 (PDT)
)
[arc-seal:] => Array
(
[0] => i=2; a=rsa-sha256; t=1602637022; cv=pass; d=google.com; s=arc-20160816; b=UI0zpjJa1fkhWM7LcJRr/x7i6gldLTzSzSOBKaqoui9lk8D8OmomRDmCeVUORYCKdn sFMd/qya/k3qcrgJlZGxHczhZu2GG7VH+EVjeQXeedxcwz5Iknn0VVUyBZKpMOM6otJn pu+KNbYssQZjBDvmtOxnaG0QS5ubDg5rsV53cDIIVyfB83KK7mv6t5HzolkwUOiU4CMv vX+5XT6RdZXT7U/zBjqtoCYNFHwAMgjGFJOXjTg4jcRXEaJNUCRzRTRRQs27iDXzEMRg ccsAJOyRapNhi5gbx7DHDqQ+JxM2jwg+vSUlYcaNJ83Te2y19cI2uIXJw9GcBQBTJiAj bI2Q==
[1] => i=1; a=rsa-sha256; t=1602637021; cv=none; d=google.com; s=arc-20160816; b=W+kogtwEuXmvQSCu/V9UngxnO07F+BSNfCHs+GEtLB2jwFpXz4tp0F2CI787XiIXZx BNRcdqnuS9RccYhXgxL+uqZM9NQSu+zHvbx4vn4dRs8zstLnVRj47flD6EbEtbsckF7f HceUKMyMa7z+/7c2/yM7MUvFGeqImCAyZJEYKjWUlJwwIz+9/tZfn8R3B7OvZ6mEBEP8 B9SYWJ+SsHwRrDgSjVfriJbE2taHaZQhzhlsiRlSufyRZqX1CEOR40YIRC3ID6bt9ESZ PKfiKMC9SBXzcOn95y/EvmkEErSgFsSwSQT/PehXtRFH+I29iRHfLr0254csDRxbi2DG eMnQ==
)
[arc-message-signature:] => Array
(
[0] => i=2; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=user-agent:content-transfer-encoding:mime-version:in-reply-to :references:subject:to:reply-to:from:date:message-id; bh=Lag8U5xnvAmk7Va7H+pTf66sI2wNkiz/IQWcWcp+xfI=; b=w0AGAVh5wx2oALVrJqe7NtPVx9wFuYF/1f0qMk3D/kKRSj5XMgyVwiPZ6ohUUj3JyA irFYf3SY1MpbKvZe7eFURHabi6AmTIzShWXji13GNlxh+T0sCL0Zs2AGk7b5McBnxEFA UIUQ8IcVoNL2SwC/FUelqC8Od84HOLuOWUkK48/83pZkYtPC3SjWCzHYL0fykrq0cuSx DR+pzvbnVZEQHwHT7X/iU6sgsAiTYhYqJoG0k7IMjWaU1knlL/cSKa9WbFdm14cfgcqC IGc+kTP7A2/LkpjKG3tzyrdjssr0OyUwDw3tl1NkELBDkXc7sRjJ2zoI0N+xxqvCL8yu Qu7w==
[1] => i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=user-agent:content-transfer-encoding:mime-version:in-reply-to :references:subject:to:reply-to:from:date:message-id; bh=Lag8U5xnvAmk7Va7H+pTf66sI2wNkiz/IQWcWcp+xfI=; b=BXGNuU5kVFs4jNl1D/z3rIGN54dz0EhzNNuZnFUL+eDlzuIwwroSRounjmIMAp7XEU cIM5maiEHs/9YhnZ8fbmdN7rHxvRQMtx7tU66TUX07Z0nkNP31t+51g1LF7ugDZ5qUD5 +ZkPogGYfa0LwX2yA6Q9GZO3QFbFw3nsvlnrAxcQc9ubkNu3c+pyFyQjgmJAsOUt7bDa P7pBH1vv1qS2HML6KgAJ+uRfH6Q+TvpI4lXoUYeP8C7v1btOR6AJchXStimSdyjfNgst H11KxC3Kc6Xit/J4UHNWvjr/UzKkDeQKduDrjgbu2JEkWwjWEob2vrtO/vkRGzYy6IvH buMg==
)
[arc-authentication-results:] => Array
(
[0] => i=2; mx.google.com; arc=pass (i=1 spf=pass spfdomain=e1m.net); spf=neutral (google.com: 209.85.220.41 is neither permitted nor denied by domain of list-admin@e1m.net) smtp.mailfrom=list-admin@e1m.net
[1] => i=1; gmr-mx.google.com; spf=pass (google.com: domain of list-admin@e1m.net designates 216.200.145.36 as permitted sender) smtp.mailfrom=list-admin@e1m.net
)
[return-path:] => Array
(
[0] =>
[1] =>
)
[received-spf:] => Array
(
[0] => neutral (google.com: 209.85.220.41 is neither permitted nor denied by domain of list-admin@e1m.net) client-ip=209.85.220.41;
[1] => pass (google.com: domain of list-admin@e1m.net designates 216.200.145.36 as permitted sender) client-ip=216.200.145.36;
)
[authentication-results:] => mx.google.com; arc=pass (i=1 spf=pass spfdomain=e1m.net); spf=neutral (google.com: 209.85.220.41 is neither permitted nor denied by domain of list-admin@e1m.net) smtp.mailfrom=list-admin@e1m.net
[x-google-dkim-signature:] => v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-original-authentication-results:x-gm-message-state:message-id :date:from:reply-to:to:subject:references:in-reply-to:mime-version :content-transfer-encoding:user-agent; bh=Lag8U5xnvAmk7Va7H+pTf66sI2wNkiz/IQWcWcp+xfI=; b=owZxtBVVWR2pkZllJo/qd7unVSVchs1tzdQ0XXtA0EL5DOR/AhL15WTCHLRVeHTJqb m4RAut3p5q+3cu7kp4v6RPYMthUcJysdLOOn0O0uD7DcMuiWPF2GLh4yrNJcqpE/eSoE zXzsIDFC3w7lACOSSt3r6BXvh3PhStNV4wg3iYe9t6QKggri8ldT+eiZRzLcaUl9fqTe /oSuectO6HXnk+5uDlXq1tTnqK7NmVniYb4MpkQUdjcHJGLR1usu7EBvCjYq70xz8pLg GMS2vG1s8l3q0lJNfwNHUs7GDowGrncTYhgnZ17vs/lGofI+uRJrjT3m4/fsSZsXFLMm 7WAQ==
[x-original-authentication-results:] => gmr-mx.google.com; spf=pass (google.com: domain of list-admin@e1m.net designates 216.200.145.36 as permitted sender) smtp.mailfrom=list-admin@e1m.net
[x-gm-message-state:] => AOAM530QH/iHyNPyCoXCiOhVgiwFRF0fjEoCr/cANl7qAiIXGCZy/ySP IL6ngAz2yxK0GpS7EUuGNAArhUqtD6rsnZp1SA==
[x-google-smtp-source:] => ABdhPJyxU5C3H+Kpqo+Psxrz0rcLS4kECdPdFJf72+pzOalxHR90ke8F3I/zrWa1c7tqE981+HHiYazh9tA8qtoMsOJrF5m7mbw=
[x-eon-delivered-to:] =>
[x-eon-originating-account:] => 4jk-hl8_s9WosyxbFJPwteLElUmjUlJLqrEy-aHJNZesmrRzmQKIcwrMu6xeFMol
[x-eon-dm:] => m0117123.ppops.net
[x-cids:] => courriel4
[message-id:] => <20201014025545.16284cqjectapjeo@courriel.upmc.fr>
[date:] => Wed, 14 Oct 2020 02:55:45 +0200
[from:] => Emilie DAVEAU
[reply-to:] => kinghussein@online-pro.org
[to:] => Christophe Antoniewski
[subject:] => Re: [ibps] TR: Phishing
[references:] => <836298F7-99AA-4E9C-960C-19C2C515CC6D@upmc.fr>
[in-reply-to:] =>
[mime-version:] => 1.0
[content-type:] => multipart/alternative; boundary="=_7ptrq9vqfps8"
[content-transfer-encoding:] => 7bit
[user-agent:] => Internet Messaging Program (IMP) H3 (4.3.11)
[x-dsiupmcsession:] => ba0b0726c1885f0841c465a76560b8c6
[x-virus-scanned:] => ClamAV using ClamSMTP
[x-eon-alias-sig:] => AQI82n9fhkyYwyDOjwEAAAAY,0a77ad7cedcdf17a6d8aef60f8f13be5
[x-proofpoint-virus-version:] => vendor=fsecure engine=2.50.10434:6.0.235,18.0.687 definitions=2020-10-13_16:2020-10-13,2020-10-13 signatures=0
[x-proofpoint-spam-details:] => rule=notspam policy=default score=0 mlxscore=0 malwarescore=0 suspectscore=0 clxscore=1011 priorityscore=1501 impostorscore=0 phishscore=0 lowpriorityscore=0 bulkscore=0 spamscore=0 mlxlogscore=959 adultscore=0 classifier=spam adjust=0 reason=mlx scancount=1 engine=8.12.0-2009150000 definitions=main-2010140002
)
Domain Names used for collecting scam email ("Honeypot email accounts") have been obscured and replaced with the token 'HUN1P0T'
Community Action - SPAM/non-Scam Report
Occasionally, incorrectly categorized emails get into the Scamdex Scam Email Database and need to be removed. If this
email has Personally Identifiable Information (PII), or is, in your opinion, from a bona-fide entity, let us know.
Scamdex will, as soon as is practicable, take-down any emails that in our opinion should not
be in our database. Note that ALL emails in the Scamdex Scam Email Database were received as Unsolicited Commercial Email, aka UCE or
SPAM, via unpublished 'Honeypot' email addresses.
King Hussein Vakfi adina, taleplerinizi iletmek için 1.000.000,00 ABD Dolari bagislamak üzere e-posta adresiniz seçildi. Ad Soyad ülke Telefon numarasi
> On peut aussi prendre le mal à la racine et signaler le fishing à
> https://www.cnil.fr/fr/spam-phishing-arnaques-signaler-pour-agir où il sera
> traité au niveau du réseau national.
> Par ailleurs, il est fréquent que les logiciels de messagerie intègrent
> directement une fonctionnalité de signalement d'un fishing. Jetez un oeil
> dans les menus contextuels des messages.
>
> Christophe Antoniewski
>
>
> Plateforme de bioinformatique ARTbio <http://artbio.fr/>
> Institut de Biologie Paris Seine <http://www.ibps.upmc.fr/en> |
> Sorbonne-Université
> Bâtiment B, 7e étage, porte 725
> 9, Quai St Bernard, - Case Courrier 25
> 75252 Paris Cedex 05
>
> Tel +33 1 44 2
> *7 70 05*Mobile +33 6 68 60 51 50
>
> Pour accéder à la PlateformeBâtiment B,
> 7e étage, Porte 725
> <https://www.google.com/maps/d/u/0/edit?mid=zmZz-3Vin5D0.kjRSV6vitXE8>
>
> https://twitter.com/ARTbio_IBPS
>
>
> Le mar. 7 avr. 2020 à 12:22, COMMERCY Françoise <
> francoise.commercy@sorbonne-universite.fr> a écrit :
>
>>
>>
>> -----Message d'origine-----
>> De : Alvaro Veronique <veronique.alvaro@upmc.fr>
>> Envoyé : mercredi 1 avril 2020 13:13
>> `A : COMMERCY Françoise <Francoise.Commercy@admp6.jussieu.fr>
>> Objet : Phishing
>>
>> Bonjour,
>>
>> En cas de tentative de phishing, le mieux est de renvoyer le mail à
>> abuse@sorbonne-universite.fr plutôt que sur la hotline, dans cette
>> période difficile.
>>
>> Merci
>>
>> Bien à vous
>>
>> Véronique Alvaro
>>
>>
>
----------------------------------------------------------------
This message was sent using IMP, the Internet Messaging Program.
King Hussein Vakfi adina, taleplerinizi iletmek için 1.000.000,00 ABD Dolari bagislamak üzere e-posta adresiniz seçildi. Ad Soyad ülke Telefon numarasi
> On peut aussi prendre le mal à la racine et signaler le fishing à
> https://www.cnil.fr/fr/spam-phishing-arnaques-signaler-pour-agir où il sera
> traité au niveau du réseau national.
> Par ailleurs, il est fréquent que les logiciels de messagerie intègrent
> directement une fonctionnalité de signalement d'un fishing. Jetez un oeil
> dans les menus contextuels des messages.
>
> Christophe Antoniewski
>
>
> Plateforme de bioinformatique ARTbio <http://artbio.fr/>
> Institut de Biologie Paris Seine <http://www.ibps.upmc.fr/en> |
> Sorbonne-Université
> Bâtiment B, 7e étage, porte 725
> 9, Quai St Bernard, - Case Courrier 25
> 75252 Paris Cedex 05
>
> Tel +33 1 44 2
> *7 70 05*Mobile +33 6 68 60 51 50
>
> Pour accéder à la PlateformeBâtiment B,
> 7e étage, Porte 725
> <https://www.google.com/maps/d/u/0/edit?mid=zmZz-3Vin5D0.kjRSV6vitXE8>
>
> https://twitter.com/ARTbio_IBPS
>
>
> Le mar. 7 avr. 2020 à 12:22, COMMERCY Françoise <
> francoise.commercy@sorbonne-universite.fr> a écrit :
>
>>
>>
>> -----Message d'origine-----
>> De : Alvaro Veronique <veronique.alvaro@upmc.fr>
>> Envoyé : mercredi 1 avril 2020 13:13
>> `A : COMMERCY Françoise <Francoise.Commercy@admp6.jussieu.fr>
>> Objet : Phishing
>>
>> Bonjour,
>>
>> En cas de tentative de phishing, le mieux est de renvoyer le mail à
>> abuse@sorbonne-universite.fr plutôt que sur la hotline, dans cette
>> période difficile.
>>
>> Merci
>>
>> Bien à vous
>>
>> Véronique Alvaro
>>
>>
>
----------------------------------------------------------------
This message was sent using IMP, the Internet Messaging Program.